US9307412B2

Method and system for evaluating security for an interactive service operation by a mobile device

Summary by NHIP

Mobile Security Evaluation Method

A security component on a mobile device evaluates an interactive service by verifying a target website's domain registration against an entity. The system generates a security evaluation using trust factors for the device, service, and network, then allows operation only if measures stay below a threshold.

Claim Score by NHIP

Read claim 22, the broadest

Abstract

A method for evaluating security during an interactive service operation by a mobile communications device includes launching, by a mobile communications device, an interactive service configured to access a server over a network during an interactive service operation, and generating a security evaluation based on a plurality of trust factors related to a current state of the mobile communications device, to a security feature of the application, and/or to a security feature of the network. When the security evaluation is generated, an action is performed based on the security evaluation.

US9307412B2, drawing sheet 1
Sheet 1 of 10

Term

6.9 yearsleft in the term

Expires 9 August 2033, including 107 days of term adjustment.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

26 claims: 3 independent, 23 dependent

  1. 1
    A method for evaluating security during an interactive service operation by a mobile communications device, the method comprising:identifying, by a security component on a mobile communications device, a launch of an interactive service configured to communicate with a server over a network during an interactive service operation, wherein the interactive service is associated with an entity and is configured to transmit data to and receive data from a target website purportedly associated with the entity;verifying that the target website is an authentic website associated with the entity, wherein the verifying includes identifying a domain of the target website based on a uniform resource locator (URL) of the target website and includes determining that the domain of the target website is registered by the entity;in response to the launch of the interactive service, generating, by the security component, a security evaluation of the interactive service based on a plurality of trust factors including: a trust factor related to a current state of the mobile communications device, a trust factor related to a security feature of the interactive service, and a trust factor related to a security feature of the network;and allowing, by the security component, the performance, by the mobile communications device, of the interactive service operation when a security measure from the security evaluation does not go beyond a threshold security measure.
  2. 21
    A method for evaluating security during an interactive service operation by a mobile communications device, the method comprising:identifying, by a mobile communications device, a launch of an interactive service configured to communicate with a server over a network during an interactive service operation, wherein the interactive service is associated with an entity and is configured to transmit data to and receive data from a target website purportedly associated with the entity;verifying that the target website is an authentic website associated with the entity, wherein the verifying includes identifying a domain of the target website based on a uniform resource locator (URL) of the target website and includes determining that the domain of the target website is registered by the entity;in response to the launch of the interactive service, determining, by the mobile communications device, a security score for the interactive service based on a plurality of trust factors including: a trust factor related to a current state of the mobile communications device, a trust factor related to a security feature of the interactive service, and a trust factor related to a security feature of the network;generating a security evaluation for the interactive service based on the security score;and displaying, by the mobile communications device, the security evaluation for the interactive service and/or a contextual information overlay associated with the interactive service comprising a checklist that includes information regarding a current security status of the mobile communications device, a security status of the interactive service, and a security status of the network, wherein the security evaluation and/or the contextual information overlay is displayed while the user is using the interactive service.
  3. 22
    Broadest claimClaim Score 38, average(NHIP)A method for evaluating security during an interactive service operation by a mobile communications device, the method comprising:receiving, by a server having a hardware processor and non-transient computer readable media, an indication from a mobile communications device that an interactive service on the mobile communications device is launched, wherein the interactive service is configured to communicate with another server over a network during an interactive service operation, and wherein the interactive service is associated with an entity and is configured to transmit data to and receive data from a target website purportedly associated with the entity;verifying that the target website is an authentic website associated with the entity, wherein the verifying includes identifying a domain of the target website based on a uniform resource locator (URL) of the target website and includes determining that the domain of the target website is registered by the entity;and in response to the indication of the launch of the interactive service, generating, by the server, a security evaluation of the interactive service based on a plurality of trust factors including: a trust factor related to a current state of the mobile communications device, a trust factor related to a security feature of the interactive service, and a trust factor related to a security feature of the network.